{"id":"CVE-2025-42599","title":"Active! mail 6 BuildInfo: 6.60.05008561 and earlier contains a stack-based buffer overflow vulnerability","summary":"Active! mail 6 BuildInfo: 6.60.05008561 and earlier contains a stack-based buffer overflow vulnerability. Receiving a specially crafted request created and sent by a remote unauthenticated attacker may lead to arbitrary code execution an…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-121"],"vendor":"qualitia","product":"active!_mail","affected":["active!_mail < 6.60.05008562"],"patched":["active!_mail 6.60.05008562"],"published":"2025-04-18","updated":"2026-09-24","sourceUpdated":"2026-09-24T13:10:00.320","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-42599","references":[{"url":"https://jvn.jp/en/jp/JVN22348866/","label":"vultures@jpcert.or.jp"},{"url":"https://www.qualitia.com/jp/news/2025/04/18_1030.html","label":"vultures@jpcert.or.jp"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-42599","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild"],"epss":0.03298,"epssPercentile":0.87985,"kev":true,"kevDateAdded":"2025-04-28","kevDueDate":"2025-05-19","kevRansomware":false,"exploited":true,"ingestedAt":"2026-09-24T13:43:25.656Z","slug":"CVE-2025-42599","body":"## Overview\n\nActive! mail 6 BuildInfo: 6.60.05008561 and earlier contains a stack-based buffer overflow vulnerability. Receiving a specially crafted request created and sent by a remote unauthenticated attacker may lead to arbitrary code execution and/or a denial-of-service (DoS) condition.\n\n## Affected\n\n- `active!_mail < 6.60.05008562`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `active!_mail 6.60.05008562`","depth":"hadal","depthScore":80,"depthScoreParts":{"impact":53.9,"likelihood":0.7,"exploitation":25,"ransomware":0},"changes":[]}